ShowDoc 2.4.1 allows remote attackers to edit other users' notes by navigating with a modified page_id.
References
Link | Resource |
---|---|
https://github.com/star7th/showdoc/issues/397 | Issue Tracking |
https://github.com/star7th/showdoc/commit/bcdb5e3519285bdf81e618b3c9b90d22bc49e13c | Patch |
https://github.com/CCCCCrash/POCs/tree/master/Web/showdoc/IncorrectAccessControl#0x02-modify | Exploit Third Party Advisory |
Configurations
Information
Published : 2018-11-28 00:29
Updated : 2019-10-02 17:03
NVD link : CVE-2018-19620
Mitre link : CVE-2018-19620
JSON object : View
CWE
CWE-425
Direct Request ('Forced Browsing')
Products Affected
showdoc
- showdoc